If you manage connected hardware for a living, the difficult part is rarely the first activation. The difficulty starts somewhere around the eleven thousandth one, where some SIMs are installed and reporting, some are sitting in a warehouse in a state nobody can name, and some are fitted to equipment a customer returned nine months ago that is still drawing a monthly line on the invoice. IoT Analytics estimated in October 2025 that there were approximately 4.1 billion cellular IoT connections in 2024, out of roughly 21.1 billion connected IoT devices overall. Every one of those cellular connections has to be ordered, provisioned, watched, paid for, and eventually taken out of service.

The platform layer that handles all of that is usually the last thing a buyer evaluates, and that ordering is backwards. Radio coverage gets three months of testing, the management platform gets a demo and a shrug, and then the deployment scales and the operations team discovers that the thing they cannot do is the thing they need to do twice a week. What follows is the sequence in the order operations teams actually hit each stage.

What a connectivity management platform actually is

A connectivity management platform, usually shortened to CMP, is the software layer that controls the state and behaviour of a fleet of SIMs. It handles the lifecycle transitions (activate, suspend, resume, decommission), it reports usage and session data; it applies policy rules such as data caps and alerts; and it exposes all of that through a portal and, in the best cases, an API.

It is worth separating three terms that get used interchangeably in sales conversations.

  • Connectivity provider. The organisation that sells you the SIM, holds the commercial relationship with the carriers, and bills you.
  • Connectivity management platform. The software itself. Some providers license a platform from a carrier, some build their own, and some resell someone else’s with their branding on it.
  • Carrier or mobile network operator. The organisation that owns the radio network the device is attached to at any given moment.

Platform capability and network coverage are separate purchases that arrive bundled, and a provider can have very good coverage and a poor portal.

Two more definitions come up constantly. SIM lifecycle states are the statuses a SIM can hold, typically inventory or test, active, suspended, and decommissioned, with billing rules attached to each. A policy engine is the automation layer that changes those states or applies limits based on a trigger, for example, suspending a SIM that has passed a usage threshold or alerting when a device stops reporting.

Stage One: The SIM Decision That Gets Made Too Fast

The first real decision is which SIM goes into the product, and it is normally made under time pressure by whoever is closest to the hardware. It is also the decision with the longest tail, because the SIM will be physically inside a sealed enclosure for the next five to ten years. Three things get decided here at once.

Form factor. Removable SIMs come as 2FF (mini), 3FF (micro), and 4FF (nano), often supplied as a tri-cut card that can be broken down to whichever size is needed. The embedded option is MFF2, a chip soldered onto the board, which survives vibration, temperature swings, and moisture far better than a card in a tray and therefore dominates in vehicles and outdoor industrial equipment. It also means the SIM can never be swapped by hand.

Profile flexibility. A standard UICC holds one operator profile, while an eUICC can hold more than one and can have profiles downloaded to it over the air after the device is in the field. The GSMA’s eSIM IoT specification, SGP.32, was written for devices with no user interface and constrained connectivity, which describes most industrial hardware, and it is still evolving (version 1.3 was published in May 2026). If there is any prospect of changing operator, entering a new country, or dealing with a network shutdown during the product’s life, eUICC keeps that door open.

Network strategy. A single-network SIM attaches to one operator, a multi-network SIM roams across partner networks under one profile, and a multi-IMSI SIM carries several operator identities and can switch between them. Each step up costs more per unit and removes a different failure mode, so the right answer is specific to a country list and a device rather than general.

Radio technology sits alongside this. LTE-M and NB-IoT are the low-power options for devices that send small amounts of data and need long battery life. They are cheaper to run and are not available everywhere, and NB-IoT in particular has patchy roaming support.

Stage Two: Provisioning, And The States Nobody Reads The Documentation For

Stage Two: Provisioning, And The States Nobody Reads The Documentation For

Once SIMs arrive, they have to be brought into a usable state without anyone touching them individually, which at any real volume means an API call or a bulk operation in the portal rather than a spreadsheet.

The mechanics are straightforward, and the billing is where people get caught. Most providers ship SIMs in an inventory or test state, which allows a small amount of data (frequently something like 50 MB or a fixed number of days) so that manufacturing can verify the device connects on the production line. That state is usually free or nearly free, and the moment a SIM leaves it, the subscription clock starts.

This creates a very common cost problem. Devices get manufactured in a batch, activated in a batch, then sit in a distributor’s warehouse for four months before anyone installs them, which means four months of subscription fees were spent on hardware that was in a box. The fix is to trigger activation from installation or first customer use, through an API call from the provisioning system or the field service app, rather than at the factory. That does require the platform to support automated activation via API, which not all of them do well.

Activation latency is the related question, because an activation request has to reach the carrier’s provisioning systems before the SIM attaches again to register the change. Minutes is normal and tens of minutes is common, and if a technician is standing at a site waiting for a device to come online, the difference between two minutes and forty is the difference between one visit and two.

Stage Three: What “Real Time” Means Once The Fleet Is Live

Every platform in this market describes its monitoring as real time, and very few of them mean the same thing by it. The reason is structural rather than a matter of engineering effort.

There are two data streams involved. Session and event data (a SIM attaching, detaching, being rejected by a network) is signalling information and can genuinely reach a platform within seconds. Usage data, meaning the bytes consumed and the charges attached to them, arrives on a slower path because it comes from carrier billing records.

For roaming traffic, there is a published ceiling on how fast that can be. The GSMA’s Near Real Time Roaming Data Exchange interface, the standard mechanism by which a visited network tells a home network what a roaming subscriber has used, enables operators to exchange roaming call information within 4 hours of the call completion. Four hours is the design target of the mechanism rather than a symptom of a slow vendor. Any provider claiming second-by-second roaming usage accuracy is either doing local estimation from its own core network, which is legitimate and worth asking about, or overselling.

The practical questions to put to a provider are therefore fairly specific.

  • How often is usage data updated in the portal, stated as a number rather than as “near real time”, and is that number different for home traffic and roaming traffic?
  • Are session events pushed out as webhooks, and does the API expose the same data as the portal at the same frequency?
  • When a usage cap is hit, how long is the gap between the actual consumption and the enforcement action?

That last question decides whether a data cap is a control or a report. If enforcement runs on a four-hour lag, a device with a stuck firmware loop can burn through a substantial overage before anything stops it.

Stage Four: Policy Automation Is Where The Money Is

Manual SIM management scales linearly with fleet size, and staff numbers do not, so the automation layer is where operational cost is either contained or lost. The rules worth setting up early are unglamorous.

  • Usage thresholds with tiered responses: an alert at 80 percent of the plan, a throttle at 100 percent, a suspension above that. Throttling is often better than suspension because the device stays reachable for diagnostics.
  • Silence alerts. A SIM that has reported nothing for a defined period indicates a failed device, a stolen device, or an install that never happened, and this tends to find more problems than usage alerts do.
  • Location or country triggers. A SIM appearing on a network it was never meant to be on is either a logistics error or a theft, and somebody should know that day.
  • Automatic state changes tied to business events, so that a cancelled subscription suspends the SIM without anyone remembering to do it.

Pooled data plans interact with all of this. In a pool, the allowances of every SIM are aggregated, and consumption is measured against the total, so a device that uses very little offsets one that uses a lot. Pooling also changes what the alerts watch, because the meaningful threshold becomes pool consumption rather than any individual SIM.

Stage Five: Isolation, Access Control, And The Security Work That Happens At The SIM

Security in this context is mostly about limiting what a compromised device or a stolen SIM can reach. The controls available at the connectivity layer are reasonably standard across the industry.

  • Private APN. Device traffic is routed into a private network segment rather than out to the public internet, which removes the device from general internet exposure.
  • IPsec VPN or a direct tunnel. The link between the mobile core and the customer’s own infrastructure is encrypted and terminated inside that infrastructure.
  • IMEI locking. The SIM is bound to a specific device identity and will not work if moved into another router.
  • Usage and destination barring. Voice, SMS and specific data destinations are blocked where the device has no legitimate need for them.

These map onto recognised device-level guidance. NIST’s IoT device cybersecurity capability core baseline, published in May 2020 as NISTIR 8259A, treats device identification and logical access control to interfaces as foundational capabilities, and SIM-level identity binding and APN isolation implement both for cellular hardware.

Doing this well is largely a procurement question, because most of these controls are decided when the SIM is bought rather than added later. Some specialist connectivity providers include them as standard rather than as an upgrade tier. Trafalgar Wireless, for example, supplies M2M SIM cards in the 2FF, 3FF and 4FF form factors, including tri-cut, as well as embedded MFF2, in both UICC and eUICC variants, and offers private APN and IPsec VPN options for network isolation alongside pooled data plans and a management portal for activation and monitoring. Its published footprint is 500 or more networks across roughly 180 countries, covering 2G, 3G, 4G/LTE and 5G as well as LTE-M and NB-IoT. The specific supplier matters less than the general point, which is that isolation options, form factor, and profile flexibility are attributes of the M2M SIM cards you order at the start, and they are difficult and expensive to retrofit once devices are sealed, installed, and out in the field.

The Exception That Ruins Deployment Plans: Permanent Roaming

Everything above assumes the SIM is allowed to stay where it is, and in several markets it is not.

Permanent roaming means a SIM from one country attaching indefinitely to a network in another, which is how most international IoT deployments work in practice, because shipping one SIM type everywhere is far simpler than sourcing local SIMs per market. Several regulators and operators restrict it. According to a July 2026 analysis published by IoT For All, Brazil, Turkey, and Nigeria have explicit restrictions, while China, India, Saudi Arabia, and the United Arab Emirates require that connectivity services be provided by a locally registered operator. The same analysis puts the typical enforcement window at somewhere around 90 to 120 days depending on the market, after which an operator that notices a SIM roaming past the permitted period may simply cut the connection. The failure mode is delayed and collective: devices deploy, they work for three or four months, everyone concludes the rollout went well, and then a whole national sub-fleet goes silent at once.

The available responses all involve localisation of some kind. Multi-IMSI SIMs can present a local identity in the affected market. An eUICC can have a local operator profile downloaded to it over the air, which is the cleaner long-term answer and the reason SGP.32 exists. Local SIMs sourced per country work as well, and they reintroduce the fragmentation the single SIM strategy was meant to avoid. Whichever route is chosen, the check has to be done per market before shipping, and repeated periodically, because the rules move.

Stage Six: Suspension, Decommissioning, And The Cost Of Zombie SIMs

The end of the lifecycle is where the largest amount of avoidable money is normally sitting, and it is the stage almost nobody builds a process for.

A zombie SIM is one that is still active and still billing while the device it belongs to has been retired, lost, stolen, or returned. They accumulate quietly: a customer cancels, a technician swaps a faulty unit and keeps the old one in a van, or an asset is scrapped without anyone telling the connectivity team. Each individual case is a few dollars a month, which is exactly why nobody escalates it, and a fleet of several thousand accumulates a meaningful annual figure.

There is a distinction between the two end states that matters commercially.

  • Suspended. The SIM cannot pass data, but the subscription usually continues at a reduced or full rate, and it can be resumed. Appropriate for seasonal equipment or a device awaiting repair.
  • Decommissioned or terminated. Billing stops. Depending on the provider and the carrier, this may be reversible for a limited window and may be permanent after that.

Two operational habits deal with most of the problem. The first is a monthly or quarterly reconciliation between the SIM inventory in the platform and the asset register in the field service or ERP system, treating any SIM with no matching live asset as a candidate for suspension. The second is automating termination from a business event, so that a cancelled contract or a scrapped asset triggers the state change through the API rather than relying on someone to remember.

Network shutdowns force a version of this on everyone eventually. As operators retire 2G and 3G on different schedules in different countries, devices built for those technologies stop working market by market, and an eUICC plus a platform that supports bulk profile changes turns the response from a truck roll into a scripted operation.